Hackers tried to use Sophos Firewall zero-day to deploy Ransomware

[correlate]

Level 18
Thread author
Top Poster
Well-known
May 4, 2019
801
Hackers tried to exploit a zero-day in the Sophos XG firewall to distribute ransomware to Windows machines but were blocked by a hotfix issued by Sophos.

At the end of April, hackers utilized a zero-day SQL injection vulnerability that leads to remote code execution in Sophos XG firewalls.
Attackers used this vulnerability to install various ELF binaries and scripts that are being named by Sophos as the Asnarök Trojan.
This Trojan was used to steal data from the firewall that could have allowed the attackers to compromise the network remotely
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top